Privacy notice

Last updated 31 August 2026

YT Growth Stack is operated by CronosPMC LLC, a company registered in the Sharjah Media City free zone (Shams), United Arab Emirates. This notice describes what the service collects, who it is sent to, and what you can ask us to do with it. It is written against what the software actually does, not against what a generic template assumes.

What we collect

  • Your account. Your email address, and, if you sign in with Google or GitHub, the name and avatar those providers return. We never receive your Google or GitHub password.
  • Launch notifications.If you explicitly ask to be notified about this product's Product Hunt launch, we store your email address, the consent time and the public form that collected it. This is separate from a product account. We use Resend to prepare the opted-in launch list. You can unsubscribe from a launch email or ask us to delete the record at any time.
  • What you ask the agent to research. Your requests, the niche and audience you describe, and everything a run produces: competitor videos, patterns, ideas, scores and briefs.
  • Usage and cost records. For every provider call: which provider, which operation, token counts and the estimated cost. This is how spend limits are enforced, so it cannot be switched off while you use the service.
  • Minimal product-measurement events. We record page openings and a small set of product milestones, such as starting or completing research, opening a cited idea or brief, saving an idea, and opening pricing. These events never include your email, research request, voice transcript, brief content, source-video URLs, or full referrer.
  • Billing records, if you buy a paid plan: a Stripe customer reference, which plan you are on, and the subscription status.
  • Standard server logs kept by our hosting provider, including IP address and user agent, for security and debugging.

Voice

When you speak to the agent, your microphone audio is streamed directly from your browser to OpenAI over an encrypted peer connection, using a short-lived credential our server mints for that session. We do not record or store your audio, and we do not store voice transcripts. What we keep from a voice session is the research request it produced and the token counts we were billed for. OpenAI’s handling of the audio is governed by its own API terms, under which data sent through the API is not used to train its models.

Who we send data to

We use a small number of processors. Each receives only what it needs to do its job.

  • Supabase — database, authentication and sign-in emails.
  • Resend — opted-in launch-notification contact management and delivery.
  • Vercel — hosting and server logs.
  • OpenAI — voice, and the models that read competitor data and write ideas and briefs.
  • Apify and Firecrawl — collecting public competitor videos and pages. These receive the search terms for a run, not your account details.
  • Stripe — payments. Card details go to Stripe directly and never reach our servers. We store only a customer reference, the plan and the subscription status.

These providers are outside the UAE, so using this service involves transferring your data abroad. Each is a major processor operating under its own data protection commitments, including standard contractual clauses where they apply.

We do not sell your data, we do not share it with advertisers, and we do not use your research content to train models.

How long we keep it

Your research history stays until you delete it or ask us to close your account. Product measurement events are retained for up to ninety days. Rate limit counters are pruned after roughly seventy days. Usage, cost and billing records are kept for as long as we need them for accounting.

Your rights

Our processing is governed by the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), which applies to controllers established in the UAE including its free zones — the financial free zones, DIFC and ADGM, run their own regimes and Shams is not one of them. Under it you may ask for a copy of your personal data, ask us to correct or erase it, ask us to restrict or stop a particular use, ask for it in a portable form, and withdraw consent you have given. If you are in the UK or the EU, the UK GDPR and the GDPR give you equivalent rights and you may exercise them here in the same way.

Write to support@cronospmc.com and we will action it. Account deletion is currently handled by hand rather than through a button in the app, so allow a few days. Deleting your account removes your workspace, projects, runs and everything derived from them.

Cookies

We set the cookies needed to keep you signed in and to complete a sign-in redirect. We also set one first-party, random product-measurement identifier for up to ninety days so we can avoid counting the same browser as a new visitor on every page load. There are no advertising or cross-site tracking cookies.

Public alpha

This service is in public alpha. It may change, break or be withdrawn. Keep your own copy of anything you rely on.

Questions about this page: support@cronospmc.com. See also our privacy notice and terms of service.